logo

Clop ransomware is now extorting 66 Cleo data-theft victims

ID: f86395e0-fda8-5b60-ae4e-f4578a2b0276

STIX ID: report--f86395e0-fda8-5b60-ae4e-f4578a2b0276

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-12-24

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Clop exploited a zero-day vulnerability in Cleo LexiCom, VLTransfer, and Harmony (CVE-2024-50623) to steal data and is publicly extorting victims—posting a partial list of 66 companies and demanding ransom negotiations within 48 hours; vendor patches exist but exploitation is active and may be bypassed, putting potentially thousands of Cleo customers at risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.